CWE-416

High likelihood

Use After Free

Parent: CWE-825 - Expired Pointer Dereference

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

7,537 vulnerabilities with CWE-416
CVE-2024-49126 HIGH
Windows LSASS - Remote Code Execution via Race Condition
CVSS 8.1
CVE-2024-49122 HIGH
Microsoft Windows 10/11, Server 2008-2012 RCE via MSMQ Race Condition
CVSS 8.1
CVE-2024-49118 HIGH
Microsoft Windows 10/11, Server 2008-2012 - RCE via MSMQ Race Condition
CVSS 8.1
CVE-2024-49116 HIGH
Windows Server 2016/2019/2022/2025 RCE via Race Condition
CVSS 8.1
CVE-2024-49115 HIGH
Windows Server RCE via Race Condition (2016, 2019, 2022, 2022 23H2, 2025)
CVSS 8.1
CVE-2024-49108 HIGH
Windows Server 2016-2025 - Remote Code Execution via Remote Desktop Services Race Condition
CVSS 8.1
CVE-2024-49106 HIGH
Windows Server RCE via Race Condition in Remote Desktop Services
CVSS 8.1
CVE-2024-49097 HIGH
Windows PrintWorkflowUserSvc - Elevation of Privilege via Race Condition
CVSS 7.0
CVE-2024-49079 HIGH
Windows 10 1507-22H2, Windows 11 22H2-24H2, Windows Server 2012-2016 - Remote Code Execution via IME Use-After-Free
CVSS 7.8
CVE-2024-49074 HIGH
Windows 10 1809, 21H2, 22H2 and Windows Server 2019 - Use-After-Free in Kernel-Mode Driver
CVSS 7.8
CVE-2024-49069 HIGH
Microsoft Excel - Remote Code Execution via Use-After-Free
CVSS 7.8
CVE-2024-47834 CRITICAL
GStreamer < 1.24.10 - Use-After-Free in Matroska Stream CodecPrivate Processing
CVSS 9.1
CVE-2024-12382 HIGH
Google Chrome < 131.0.6778.139 - Use-After-Free in Translate
CVSS 8.8
CVE-2024-53953 HIGH
Adobe Animate < 23.0.9 - Use-After-Free via Malicious File
CVSS 7.8
CVE-2024-52997 HIGH
Photoshop Desktop 26.0 and earlier - Use-After-Free
CVSS 7.8
CVE-2024-49530 HIGH
Acrobat Reader <24.005.20307 - Use After Free
CVSS 7.8
CVE-2024-53143 HIGH
Linux Kernel 6.10-6.10, 6.11-6.11.10, 6.12-6.12.1, 6.13 - Use-After-Free in fsnotify Superblock Handling
CVSS 7.8
CVE-2024-38927 CRITICAL
Open Robotics Robotic Operating System 2 and Nav2 humble - Use-After-Free via nav2_amcl Dynamic Parameter
CVSS 9.8
CVE-2024-38926 CRITICAL
Open Robotics Robotic Operating System 2 and Nav2 humble - Use-After-Free via nav2_amcl Dynamic Parameter
CVSS 9.8
CVE-2024-38925 CRITICAL
Open Robotics Robotic Operating System 2 and Nav2 humble - Use-After-Free via nav2_amcl Dynamic Parameter
CVSS 9.8
CVE-2024-38924 CRITICAL
Open Robotics Robotic Operating System 2 and Nav2 - Use-After-Free via nav2_amcl Dynamic Parameter
CVSS 9.8
CVE-2024-38923 CRITICAL
Open Robotics Robotic Operating System 2 and Nav2 humble - Use-After-Free via nav2_amcl Dynamic Parameter
CVSS 9.8
CVE-2024-38921 CRITICAL
Open Robotics Robotic Operating System 2 and Nav2 humble - Use-After-Free via nav2_amcl Dynamic Parameter
CVSS 9.8
CVE-2024-38920 CRITICAL
Open Robotics ROS2 and Nav2 humble - Use-After-Free via nav2_amcl Dynamic Parameter
CVSS 9.1
CVE-2024-38910 HIGH
Open Robotics ROS2 & Nav2 - Use After Free
CVSS 7.5
Details
Vulnerabilities 7,537
Exploit Likelihood High